<oembed><type>rich</type><version>1.0</version><author_name>npub1j66aek8wm7jq8vaffs2l8w43evyywd4q7tcnqyge6xqezz0vcpks7jm42m</author_name><author_url>https://nostr.ae/npub1j66aek8wm7jq8vaffs2l8w43evyywd4q7tcnqyge6xqezz0vcpks7jm42m</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-11-02&#xA;📝 Original message:On 11/01/2013 10:01 PM, bitcoingrant at gmx.com wrote:&#xA;&#xA;&gt; Server provides a token for the client to sign.&#xA;&#xA;Anyone else concerned about signing an arbitrary string?  Could be a&#xA;hash of $EVIL_DOCUMENT, no?  I&#39;d want to XOR the string with my own&#xA;randomly generated nonce, sign that, then pass the nonce and the&#xA;signature back to the server for verification.&#xA;&#xA;-- &#xA;Johnathan Corgan, Corgan Labs&#xA;SDR Training and Development Services&#xA;http://corganlabs.com&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: johnathan.vcf&#xA;Type: text/x-vcard&#xA;Size: 334 bytes&#xA;Desc: not available&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131102/09685fb5/attachment.vcf&gt;&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 230 bytes&#xA;Desc: OpenPGP digital signature&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131102/09685fb5/attachment.sig&gt;</html></oembed>